Sign inSign up

gravwell/packetfleet

By gravwell

•Updated over 5 years ago

Gravwell On-the-fly packet capture ingester

Image
0

752

gravwell/packetfleet repository overview

Refer to Gravwell's Docker guide⁠ for information on how to deploy ingester containers.

The Packet Fleet Ingester provides a mechanism to query Google Stenographer instances and have results ingested per-packet into Gravwell. Full documentation is available⁠.

The packetfleet optionally takes several environment variables as configuration overrides (defaults shown):

LISTEN_ADDR=":443"              # Host:Port to listen on
TLS=true                        # Use TLS (default is true, set to false to disable TLS)
URL="https://127.0.0.1:1234"    # URL to Stenographer
INTERFACE=eth0                  # interface stenographer should listen on
STENO_HOST=127.0.0.1            # stenographer host to bind to 
STENO_PORT=1234                 # stenographer port to bind to
STENO_SYSLOG=true               # enable/disable syslog output for stenographer (default is false)
DISABLE_PACKET_FLEET=FALSE      # set to true to disable the packet fleet service and only run stenographer
DISABLE_STENOGRAPHER=FALSE      # set to true to disable stenographer and only run packet fleet

Each Stenographer ingester listens on a given port (Listen-Address) and accepts Stenographer queries as an HTTP POST. On receiving a query, the ingester returns an integer job ID, and asynchronously queries the Stenographer instance and begins to ingest the returned PCAP. Multiple in-flight queries can be ran concurrently. Job status can be viewed by issuing an HTTP GET on "/status", which returns a JSON-encoded array of in-flight job IDs.

A simple web interface to submit and view job status is also available by browsing to the specified ingester port.

You can optionally disable either Packet Fleet or Stenographer within the container, in order to simplify deployment considerations without having to create new container images.

See https://docs.gravwell.io⁠ for more information on configuring the Packet Fleet ingester.

An example docker invocation:

docker run --name packetfleet -d --cap-add IPC_LOCK --cap-add NET_ADMIN \
    -e GRAVWELL_CLEARTEXT_TARGETS="192.168.1.1,192.168.1.2" \
    -e GRAVWELL_INGEST_SECRET="IngestSecrets" \
    -e LISTEN_ADDR=":443" \
    -e INTERFACE="eth1" \
    -e STENO_SYSLOG=true \
    -v /dev/log:/dev/log \
    --network=host gravwell/packetfleet:latest

See https://github.com/gravwell/gravwell/tree/master/ingesters/PacketFleet⁠ for source.

Note: The Packet Fleet ingester requires a Linux host.

Tag summary

Content type

Image

Digest

Size

119.6 MB

Last updated

over 5 years ago

docker pull gravwell/packetfleet